Security overview
Cloud Certainty Secure Browser keeps risky web content away from your users' devices and your network, and keeps your data inside your own AWS account. This page summarises how. For a detailed security review under NDA, contact [email protected].
Runs entirely in your AWS account
You deploy the product with one CloudFormation stack in your own AWS account and Region. Sessions, browsing, user identities, settings, audit records and logs all stay there. Cloud Certainty runs no service in the path of your sessions and has no access to your account.
No inbound access to browser sessions
Browser sessions run in your VPC and accept no inbound network connections: there is no load balancer in front of them and no open port to reach them on. They connect outwards only, on port 443. In private subnets they have no public IP address at all.
Every session isolated and discarded
Each session is a separate, single-use container with its own isolated compute environment. It is created when a user starts a session and destroyed when the session ends, together with everything in it: pages, cookies, cache, history and files. Nothing carries over to the next session, and no two users or sessions share a browser.
Web content runs only in that container. Your users' devices receive a video stream of the page, not the page itself, so malicious code on a website never reaches the endpoint.
Encrypted streaming
The stream between the user's browser and the session is end-to-end encrypted (WebRTC with DTLS-SRTP) and relayed through AWS-managed relay servers on port 443, which see only encrypted traffic. The portal is served over HTTPS only, with a strict content security policy.
Your identity provider, your MFA
Users sign in through AWS IAM Identity Center, your SAML 2.0 or OIDC identity provider, or users you manage in Amazon Cognito. Your existing sign-in policies and multi-factor authentication apply. Every request is authenticated, and access is granted by verified email address and group membership, so users can't give themselves access. Users managed in Cognito must use multi-factor authentication.
Admin controls for data movement
Administrators decide, per user or group, what may leave or enter a session:
- clipboard copy out and paste in, each direction separately;
- file upload and download, with a size limit, and printing;
- which websites are reachable, through allow and block lists;
- developer tools, extensions and incognito mode;
- idle, disconnect and maximum session timeouts;
- which networks may use the portal, through an IP allow list.
These rules are enforced inside the session, not just hidden in the user interface. The defaults are restrictive: no clipboard, no file transfer and no printing until you allow them.
Audit log
Session starts and ends, refused access, configuration changes, file transfers and clipboard use are recorded in an audit log in your account. File transfers are recorded with name, size and a fingerprint of the content; content and clipboard text are never recorded. The log is also written to Amazon CloudWatch Logs so you can forward it to your SIEM, and AWS CloudTrail records the AWS activity behind each session.
Encryption at rest
Settings, audit records and logs are encrypted at rest. You can use your own customer managed AWS KMS key.
No customer data sent to Cloud Certainty
The product sends no customer data to Cloud Certainty. Billing runs through AWS Marketplace, which tells us only how many session-hours each subscribing account used. An optional daily update check downloads a public file that lists the latest release; it sends no account, stack or user information and can be turned off.
Regular security updates
We ship browser security fixes promptly. Critical or actively exploited browser vulnerabilities are fixed in a new release within 72 hours of the fixed browser package being available; other security updates within 14 days; and the browser image is refreshed at least monthly. Your admin console, and optionally email or chat notifications, tell you when a release is available, and security releases are clearly marked. Releases are immutable, and you decide when to upgrade.
Your part
- Protect the first-admin account and require MFA in your identity provider.
- Use private subnets with a NAT gateway. Add DNS filtering or a network firewall if your policy requires it.
- Restrict the portal to your corporate networks with the IP allow list, if appropriate.
- Forward the audit log and CloudTrail to your SIEM.
- Upgrade promptly when a security release is announced.
Something unclear or missing? Email [email protected].